Employees across organizations are using AI to harness its potential to automate, coordinate, and optimize complex workflows. Some of that happens through tools IT has reviewed and approved. A lot of it happens through personal accounts and browser extensions nobody in security has ever seen, let alone signed off on.

The familiar security playbook to minimize AI risk is to discover the AI tools in use. Gate access with CASB, adding DLP rules to the mix, and tracking their usage. While this is not a bad security model (considering that its worked for years to secure SaaS sprawl) it has its limitations when it comes to AI.

Why CASB and DLP Fall Short for AI

Unlike conventional SaaS risk, which can be confined to an app, a file, or a structured data field, AI risk is a different animal. It rears its head in a prompt. It shows up in the response generated by the AI model. And in a scenario that organizations have come to dread, it comes up in action that autonomous agents take because of a malicious prompt.

Unfortunately, none of these scenarios always cleanly align with what CASB and DLP were built to inspect.